Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

Debian 10 Security Advisory DLA-3157-1: BlueZ Vulnerability Risk to DoS

debian lts
Calendar Grey October 24, 2022
Dist Debian Esm H88
Multiple security flaws identified in BlueZ could result in Denial of Service and potential data exposure. It is advised to apply updates for Debian 10 to improve system security.
Several vulnerabilities were discovered in BlueZ, the Linux Bluetooth protocol stack

Summary

CVE-2019-8921

SDP infoleak, the vulnerability lies in the handling of a
SVC_ATTR_REQ by the SDP implementation of BlueZ. By crafting a
malicious CSTATE, it is possible to trick the server into
returning more bytes than the buffer actually holds, resulting in
leaking arbitrary heap data.

CVE-2019-8922

SDP Heap Overflow; this vulnerability lies in the SDP protocol
handling of attribute requests as well. By requesting a huge
number of attributes at the same time, an attacker can overflow
the static buffer provided to hold the response.

CVE-2021-41229

sdp_cstate_alloc_buf allocates memory which will always be hung in
the singly linked list of cstates and will not be freed. This will
cause a memory leak over time. The data can be a very large
object, which can be caused by an attacker continuously sending
sdp packets and this may cause the service of the target device to
crash.

CVE-2021-43400

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: bluez
Version: 5.50-1.2~deb10u3
CVE ID: CVE-2019-8921 CVE-2019-8922 CVE-2021-41229 CVE-2021-43400
Debian Bug: 998626 1000262 1003712

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here